Class: Awspec::Type::SecurityGroup

Inherits:
ResourceBase show all
Defined in:
lib/awspec/type/security_group.rb

Constant Summary

Constants included from Helper::Finder

Helper::Finder::CLIENTS, Helper::Finder::CLIENT_OPTIONS

Instance Attribute Summary

Attributes inherited from Base

#account

Instance Method Summary collapse

Methods inherited from ResourceBase

aws_resource, #exists?, #initialize

Methods inherited from Base

#inspect, #method_missing, tags_allowed, #to_s

Methods included from BlackListForwardable

#method_missing_via_black_list

Methods included from Helper::Finder::Kinesis

#find_kinesis_by_stream_name

Methods included from Helper::Finder::Apigateway

#find_apigateway_by_id, #find_apigateway_by_name

Methods included from Helper::Finder::Codebuild

#find_codebuild_project, #select_all_codebuild_projects

Methods included from Helper::Finder::Cloudformation

#find_cloudformation_stack

Methods included from Helper::Finder::SsmParameter

#find_parameter_tag, #find_ssm_parameter

Methods included from Helper::Finder::Sqs

#find_queue

Methods included from Helper::Finder::Dynamodb

#find_dynamodb_table

Methods included from Helper::Finder::CloudwatchLogs

#find_cloudwatch_logs_group, #find_cloudwatch_logs_metric_fileter_by_log_group_name, #find_cloudwatch_logs_stream_by_log_group_name, #find_cloudwatch_logs_subscription_fileter_by_log_group_name, #select_all_cloudwatch_logs_log_groups

Methods included from Helper::Finder::AccountAttributes

#find_ec2_account_attributes, #find_lambda_account_settings, #find_rds_account_attributes, #find_ses_send_quota

Methods included from Helper::Finder::Acm

#find_certificate, #select_all_certificates

Methods included from Helper::Finder::Waf

#find_waf_ip_set, #find_waf_rule, #find_waf_web_acl

Methods included from Helper::Finder::Cloudtrail

#find_trail, #get_trail_status, #is_logging?, #select_all_trails

Methods included from Helper::Finder::Elastictranscoder

#find_pipeline

Methods included from Helper::Finder::Cloudfront

#find_cloudfront_distribution

Methods included from Helper::Finder::Ami

#find_ami

Methods included from Helper::Finder::Directconnect

#find_virtual_interface, #select_virtual_interfaces

Methods included from Helper::Finder::Ses

#find_ses_identity

Methods included from Helper::Finder::CloudwatchEvent

#find_cloudwatch_event, #select_all_cloudwatch_events

Methods included from Helper::Finder::Cloudwatch

#find_cloudwatch_alarm, #select_all_cloudwatch_alarms

Methods included from Helper::Finder::Elasticsearch

#find_elasticsearch_domain, #select_all_elasticsearch_domains

Methods included from Helper::Finder::Elasticache

#find_cache_cluster, #find_cache_subnet_group

Methods included from Helper::Finder::Kms

#find_kms_key, #find_kms_key_by_alias, #select_all_kms_aliases

Methods included from Helper::Finder::Iam

#select_all_attached_policies, #select_all_iam_groups, #select_all_iam_roles, #select_all_iam_users, #select_attached_entities, #select_attached_groups, #select_attached_roles, #select_attached_users, #select_iam_group_by_user_name, #select_policy_evaluation_results

Methods included from Helper::Finder::Lambda

#find_lambda, #select_all_lambda_functions, #select_event_source_by_function_arn

Methods included from Helper::Finder::Elb

#find_elb, #select_all_elb_tags, #select_elb_by_vpc_id

Methods included from Helper::Finder::Ebs

#find_ebs, #select_all_attached_ebs, #select_ebs_by_instance_id

Methods included from Helper::Finder::Autoscaling

#find_autoscaling_group, #find_block_device_mapping, #find_launch_configuration, #select_alb_target_group_by_autoscaling_group_name, #select_lb_target_group_by_autoscaling_group_name

Methods included from Helper::Finder::S3

#find_bucket, #find_bucket_acl, #find_bucket_cors, #find_bucket_lifecycle_configuration, #find_bucket_logging, #find_bucket_policy, #find_bucket_tag, #find_bucket_versioning, #select_all_buckets

Methods included from Helper::Finder::Route53

#find_hosted_zone, #select_record_sets_by_hosted_zone_id

Methods included from Helper::Finder::Rds

#find_rds, #select_all_rds_db_cluster_parameters, #select_all_rds_db_parameters, #select_rds_by_vpc_id

Methods included from Helper::Finder::SecurityGroup

#describe_security_groups, #find_security_group, #select_security_group_by_group_id, #select_security_group_by_group_name, #select_security_group_by_tag_name, #select_security_group_by_vpc_id

Methods included from Helper::Finder::Firehose

#find_delivery_stream

Methods included from Helper::Finder::Efs

#find_efs, #find_efs_tags, #get_id_by_name_tag, #get_name_by_id, #select_all_file_systems

Methods included from Helper::Finder::Ecs

#find_ecs_cluster, #find_ecs_container_instance, #find_ecs_container_instances, #find_ecs_service, #find_ecs_task_definition, #select_ecs_container_instance_arn_by_cluster_name

Methods included from Helper::Finder::Ecr

#find_ecr_repository

Methods included from Helper::Finder::Ec2

#find_ec2, #find_ec2_attribute, #find_ec2_status, #find_nat_gateway, #find_network_interface, #find_vpn_connection, #select_ec2_by_vpc_id, #select_eip_by_instance_id, #select_eip_by_public_ip, #select_internet_gateway_by_vpc_id, #select_nat_gateway_by_vpc_id, #select_network_interface_by_instance_id, #select_network_interface_by_vpc_id

Methods included from Helper::Finder::Subnet

#find_subnet, #select_subnet_by_vpc_id

Methods included from Helper::Finder::Vpc

#find_network_acl, #find_route_table, #find_vpc, #find_vpc_peering_connection, #select_network_acl_by_vpc_id, #select_route_table_by_vpc_id, #select_vpc_peering_connection_by_vpc_id

Methods included from Helper::Finder::Alb

#find_alb, #find_alb_listener, #find_alb_target_group, #select_alb_by_vpc_id, #select_rule_by_alb_listener_id

Methods included from Helper::Finder::Nlb

#find_nlb, #find_nlb_listener, #find_nlb_target_group, #select_nlb_by_vpc_id, #select_rule_by_nlb_listener_id

Constructor Details

This class inherits a constructor from Awspec::Type::ResourceBase

Dynamic Method Handling

This class handles dynamic methods through the method_missing method in the class Awspec::Type::Base

Instance Method Details

#idObject



10
11
12
# File 'lib/awspec/type/security_group.rb', line 10

def id
  @id ||= resource_via_client.group_id if resource_via_client
end

#inboundObject



58
59
60
61
# File 'lib/awspec/type/security_group.rb', line 58

def inbound
  @inbound = true
  self
end

#inbound_opened?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


24
25
26
27
28
# File 'lib/awspec/type/security_group.rb', line 24

def inbound_opened?(port = nil, protocol = nil, cidr = nil)
  resource_via_client.ip_permissions.find do |permission|
    cidr_opened?(permission, cidr) && protocol_opened?(permission, protocol) && port_opened?(permission, port)
  end
end

#inbound_opened_only?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


30
31
32
33
34
35
36
37
38
39
# File 'lib/awspec/type/security_group.rb', line 30

def inbound_opened_only?(port = nil, protocol = nil, cidr = nil)
  permissions = resource_via_client.ip_permissions.select do |permission|
    protocol_opened?(permission, protocol) && port_opened?(permission, port)
  end
  cidrs = []
  permissions.each do |permission|
    permission.ip_ranges.select { |ip_range| cidrs.push(ip_range.cidr_ip) }
  end
  cidrs == Array(cidr)
end

#inbound_rule_countObject



78
79
80
81
82
# File 'lib/awspec/type/security_group.rb', line 78

def inbound_rule_count
  resource_via_client.ip_permissions.reduce(0) do |sum, permission|
    sum += permission.ip_ranges.count + permission.user_id_group_pairs.count
  end
end

#ip_permissions_countObject Also known as: inbound_permissions_count



68
69
70
# File 'lib/awspec/type/security_group.rb', line 68

def ip_permissions_count
  resource_via_client.ip_permissions.count
end

#ip_permissions_egress_countObject Also known as: outbound_permissions_count



73
74
75
# File 'lib/awspec/type/security_group.rb', line 73

def ip_permissions_egress_count
  resource_via_client.ip_permissions_egress.count
end

#opened?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


14
15
16
17
# File 'lib/awspec/type/security_group.rb', line 14

def opened?(port = nil, protocol = nil, cidr = nil)
  return inbound_opened?(port, protocol, cidr) if @inbound
  outbound_opened?(port, protocol, cidr)
end

#opened_only?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


19
20
21
22
# File 'lib/awspec/type/security_group.rb', line 19

def opened_only?(port = nil, protocol = nil, cidr = nil)
  return inbound_opened_only?(port, protocol, cidr) if @inbound
  outbound_opened_only?(port, protocol, cidr)
end

#outboundObject



63
64
65
66
# File 'lib/awspec/type/security_group.rb', line 63

def outbound
  @inbound = false
  self
end

#outbound_opened?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


41
42
43
44
45
# File 'lib/awspec/type/security_group.rb', line 41

def outbound_opened?(port = nil, protocol = nil, cidr = nil)
  resource_via_client.ip_permissions_egress.find do |permission|
    cidr_opened?(permission, cidr) && protocol_opened?(permission, protocol) && port_opened?(permission, port)
  end
end

#outbound_opened_only?(port = nil, protocol = nil, cidr = nil) ⇒ Boolean

Returns:

  • (Boolean)


47
48
49
50
51
52
53
54
55
56
# File 'lib/awspec/type/security_group.rb', line 47

def outbound_opened_only?(port = nil, protocol = nil, cidr = nil)
  permissions = resource_via_client.ip_permissions_egress.select do |permission|
    protocol_opened?(permission, protocol) && port_opened?(permission, port)
  end
  cidrs = []
  permissions.each do |permission|
    permission.ip_ranges.select { |ip_range| cidrs.push(ip_range.cidr_ip) }
  end
  cidrs == Array(cidr)
end

#outbound_rule_countObject



84
85
86
87
88
# File 'lib/awspec/type/security_group.rb', line 84

def outbound_rule_count
  resource_via_client.ip_permissions_egress.reduce(0) do |sum, permission|
    sum += permission.ip_ranges.count + permission.user_id_group_pairs.count
  end
end

#resource_via_clientObject



6
7
8
# File 'lib/awspec/type/security_group.rb', line 6

def resource_via_client
  @resource_via_client ||= find_security_group(@display_name)
end